<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from rtf -->
<style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<font face="Arial" size="2"><span style="font-size:10pt;">
<div>Dear all,</div>
<div>Please find below the preliminary minutes of our call pn Nov 13<font size="1"><span style="font-size:6.65pt;"><sup>th</sup></span></font> 2018.</div>
<div>In case of any error or misunderstanding, please let me know.</div>
<a name="BM_BEGIN"></a>
<div style="margin-top:24pt;"><font face="Cambria" size="4" color="#365F91"><span style="font-size:14pt;"><b>Roll Call</b></span></font></div>
<div>John Bradley</div>
<div>Philippe Clement (Orange)</div>
<div>Bjorn Hjelm (Verizon)</div>
<div>Brian Campbell (Ping Identity)</div>
<div>Dave</div>
<div>Geoffrey Graham</div>
<div>Joseph Heenan</div>
<div>Petteri (Ubisecure)</div>
<div>Charles Marais (Orange)</div>
<div style="margin-top:24pt;"><font face="Cambria" size="4" color="#365F91"><span style="font-size:14pt;"><b>Adoption of the Agenda [Bjorn/John]</b></span></font></div>
<div>Agenda agreed</div>
<div style="margin-top:24pt;"><font face="Cambria" size="4" color="#365F91"><span style="font-size:14pt;"><b>External Organizations</b></span></font></div>
<div style="margin-top:10pt;"><font face="Cambria" size="3" color="#4F81BD"><span style="font-size:13pt;"><b>IETF 103 [John]</b></span></font></div>
<div>No specific things addressing actual work in MODRNA. The Security guidance document is under discussions, subjects like protection of the token from injection replay are discussed.</div>
<div style="margin-top:10pt;"><font face="Cambria" size="3" color="#4F81BD"><span style="font-size:13pt;"><b>GSMA [Siva]</b></span></font></div>
<div>Not addressed</div>
<div style="margin-top:24pt;"><font face="Cambria" size="4" color="#365F91"><span style="font-size:14pt;"><b>Working Group Updates</b></span></font></div>
<div style="margin-top:10pt;"><font face="Cambria" size="3" color="#4F81BD"><span style="font-size:13pt;"><b>FAPI WG [Dave]</b></span></font></div>
<div>No particular activity to mention</div>
<div style="margin-top:24pt;"><font face="Cambria" size="4" color="#365F91"><span style="font-size:14pt;"><b>Spec. Status</b></span></font></div>
<div style="margin-top:10pt;"><font face="Cambria" size="3" color="#4F81BD"><span style="font-size:13pt;"><b>CIBA Core/MODRNA [Dave/Brian/Gonzalo/Axel]</b></span></font></div>
<div>Pull requests under progression</div>
<div style="margin-top:10pt;"><font face="Cambria" size="3" color="#4F81BD"><span style="font-size:13pt;"><b>Discovery [John/Torsten]</b></span></font></div>
<div>All <font face="Wingdings">à</font> have a look at <a href="https://bitbucket.org/openid/mobile/issues/87/discovery-clean-up-draft-for-implementors"><font color="blue"><u>issue 87</u></font></a> to access the specs.</div>
<div style="margin-top:24pt;"><font face="Cambria" size="4" color="#365F91"><span style="font-size:14pt;"><b>Issue Tracker</b></span></font></div>
<div style="margin-top:10pt;"><font face="Cambria" size="3" color="#4F81BD"><span style="font-size:13pt;"><b>CIBA [Dave/Brian/Gonzalo/Axel]</b></span></font></div>
<div>.</div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"><a href="https://bitbucket.org/openid/mobile/issues/114/ciba-slow_down"><font face="Segoe UI" size="2" color="#172B4D"><span style="font-size:10.5pt;"><u>#114: CIBA: slow_down</u></span></font></a></span></font></div>
<div>Consensus appears on not updating text but rely instead on device flow. </div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"> </span></font></div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"><a href="https://bitbucket.org/openid/mobile/issues/112/ciba-require-presence-of-jwks_uri"><font face="Segoe UI" size="2" color="#172B4D"><span style="font-size:10.5pt;"><u>#112: CIBA: Require
presence of jwks_uri conditionally</u></span></font></a></span></font></div>
<div>Related to 72 as well. Update needed to the text. </div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"> </span></font></div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"><a href="https://bitbucket.org/openid/mobile/issues/115/ciba-how-about"><font face="Segoe UI" size="2" color="#172B4D"><span style="font-size:10.5pt;"><u>#115: CIBA: How about backchannel_notification_endpoint?</u></span></font></a></span></font></div>
<div>Dave proposes the term backchannel_client_notification_endpoint , consensus on the proposal</div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"> </span></font></div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"><a href="https://bitbucket.org/openid/mobile/issues/116/ciba-how-about"><font face="Segoe UI" size="2" color="#172B4D"><span style="font-size:10.5pt;"><u>#116: CIBA: How about backchannel_notification_token?</u></span></font></a></span></font></div>
<div>The term client_notification_token is kept</div>
<div><font face="Calibri" size="2" color="#172B4D"><span style="font-size:11pt;"> </span></font></div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"><a href="https://bitbucket.org/openid/mobile/issues/117/ciba-other-request-parameters-when-request"><font face="Segoe UI" size="2" color="#172B4D"><span style="font-size:10.5pt;"><u>#117: CIBA:
other request parameters when "request" is present</u></span></font></a></span></font></div>
<div>Autentication request parameters MUST be inserted solely into the JWT</div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"> </span></font></div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"><a href="https://bitbucket.org/openid/mobile/issues/109/update-ciba-examples"><font face="Segoe UI" size="2" color="#172B4D"><span style="font-size:10.5pt;background-color:whitesmoke;"><u>#109:
Update CIBA examples</u></span></font></a></span></font></div>
<div>Feel free to comment or propose examples</div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"> </span></font></div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"><a href="https://bitbucket.org/openid/mobile/issues/113/ciba-the-behavior-when-the-openid-scope"><font face="Segoe UI" size="2" color="#172B4D"><span style="font-size:10.5pt;background-color:whitesmoke;"><u>#113:
CIBA: the behavior when the "openid" scope value is not present</u></span></font></a></span></font></div>
<ul style="margin:0;padding-left:36pt;">
<li>Brian to update the text to mention why the behavior is unspecified and it could be defined elsewhere</li></ul>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"> </span></font></div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"> </span></font></div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"><a href="https://bitbucket.org/openid/mobile/issues/111/ciba-rt_hash"><font face="Segoe UI" size="2" color="#172B4D"><span style="font-size:10.5pt;"><u>#111: CIBA: rt_hash</u></span></font></a></span></font></div>
<div>Make public names would avoid collisions. </div>
<div>Consensus to keep the public claim name.</div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"> </span></font></div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"><a href="https://bitbucket.org/openid/mobile/issues/62/ciba-support-for-spam-prevention-code-in"><font face="Segoe UI" size="2" color="#172B4D"><span style="font-size:10.5pt;"><u>#62: CIBA - Support
for Spam Prevention code in Authentication Request</u></span></font></a></span></font></div>
<div>Bunch of conflicts. Needs to be resolved</div>
<ul style="margin:0;padding-left:36pt;">
<li>Petteri to work on it.</li><li>All to re read the pull request.</li></ul>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"> </span></font></div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"><a href="https://bitbucket.org/openid/mobile/issues/106/ciba-means-to-request-claims-to-be"><font face="Segoe UI" size="2" color="#172B4D"><span style="font-size:10.5pt;background-color:whitesmoke;"><u>#106:
CIBA: Means to request claims to be embedded in the issued ID token</u></span></font></a></span></font></div>
<div>No obvious real Use Case. No specific to the MODRNA profile.</div>
<div>Double check the text. (additional parameters ignored)</div>
<ul style="margin:0;padding-left:36pt;">
<li>Brian: to double check the text, and close it.</li></ul>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"> </span></font></div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"><a href="https://bitbucket.org/openid/mobile/issues/103/ciba-means-to-require-acr-as-essential"><font face="Segoe UI" size="2" color="#172B4D"><span style="font-size:10.5pt;background-color:whitesmoke;"><u>#103:
CIBA: Means to require "acr" as "essential"</u></span></font></a></span></font></div>
<div>Must the acr be included in the id_token ?</div>
<div>What is “essential” ? </div>
<ul style="margin:0;">
<li>Brian to update the text.</li></ul>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"> </span></font></div>
<div style="margin-top:10pt;"><font face="Cambria" size="3" color="#4F81BD"><span style="font-size:13pt;"><b>Discovery [John/Torsten]</b></span></font></div>
<div style="margin-top:24pt;"><font face="Cambria" size="4" color="#365F91"><span style="font-size:14pt;"><b>AOB</b></span></font></div>
<div>Meeting at same times nov 20th for CIBA, And on 27th for usual call </div>
<div><font face="Calibri" size="2" color="#365F91"><span style="font-size:11pt;"> </span></font></div>
<div><font face="Calibri" size="2"><span style="font-size:11pt;"> </span></font></div>
</span></font>
<PRE>_________________________________________________________________________________________________________________________
Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.
This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.
</PRE></body>
</html>